CVE-2025-20284: Cisco Identity Services Engine

High severity, CVSS 7.2. EPSS: 19.1% chance of exploitation in the next 30 days.

A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system as root. This vulnerability is due to insufficient validation of user-supplied input. An attacker with valid credentials could exploit this vulnerability by submitting a crafted API request. A successful exploit could allow the attacker to execute commands as the root user. To exploit this vulnerability, the attacker must have valid high-privileged credentials.

Affected products

  • Cisco Identity Services Engine: before 3.3.0 (fixed in 3.3.0); version 3.3.0 only; version 3.4.0 only
  • Cisco Identity Services Engine Passive Identity Connector: before 3.3.0 (fixed in 3.3.0); version 3.3.0 only; version 3.4.0 only

Published 2025-07-16. Last modified 2026-06-17.